Elastic has disclosed a critical vulnerability in its Elastic Cloud Enterprise (ECE) platform that allows malicious administrators to execute arbitrary commands and extract sensitive data. The vulnerability, tracked as CVE-2025-37729 under advisory ESA-2025-21 , results from improper neutralization of special elements in the Jinjava template engine .
See also: Vulnerability in Kibana Crowdstrike Connector exposes protected credentials

This issue affects multiple versions of ECE, potentially exposing enterprise environments to serious risks if exploited by internal users or compromised administrator accounts. The vulnerability occurs when specially crafted strings containing Jinjava variables are evaluated when editing deployment plans in the Elastic Cloud Enterprise admin console.
Attackers with administrative privileges can inject malicious payloads into these designs, leading to code execution. The results of these executions can then be read via logged files, allowing data theft or further system compromise.
Elastic emphasizes that the exploit requires access to the admin console and a deployment with Logging+Metrics enabled , limiting the risk to privileged users but increasing the impact in shared or multi-tenant environments.
See also: Hackers bypass Windows MoTW files with LNK Stomping

This vulnerability affects ECE versions 2.5.0 through 3.8.1, as well as versions 4.0.0 through 4.0.1. Organizations using these versions face increased exposure, particularly those using Elastic Cloud Enterprise for cloud management at scale in logging and measurement workloads.
The CVSS v3.1 score of 9.1 highlights its criticality, indicating network accessibility, low complexity, high required privileges, but a scope change that allows high impact on confidentiality, integrity, and availability. Although no PoCs have been publicly published, the advisory describes how attackers could create payloads that mimic interpreter commands.
Elastic notes that the issue does not affect standalone components of the Elastic Stack, but is specific to the ECE enterprise deployment orchestration. The company urges immediate upgrades to versions with patches 3.8.2 or 4.0.2, which address the vulnerability in the template engine. For those who cannot immediately apply patches, there are no immediate workarounds, although organizations can restrict access to the admin console through strict role-based controls and monitoring.
See also: Drift hacks: 1.5 billion Salesforce files in the hands of ShinyHunters

To detect potential exploitation, Elastic recommends scanning request files with the query: (payload.name : int3rpr3t3r or payload.name : forPath). This can flag suspicious activity that suggests injected payloads. As enterprises increasingly rely on Elastic Cloud Enterprise for hybrid cloud observability, this vulnerability highlights the need for careful privilege management.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
